CISA KEV 정보
| 취약점명 | F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability |
|---|---|
| 설명 | F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages. |
| 조치사항 | Apply updates per vendor instructions. |
| 랜섬웨어 캠페인 악용 | Known |
| CWE | CWE-22 |
| 등록일 (KEV) | 2021-11-03 |
| 조치 기한 | 2022-05-03 |
| 추가 참고 | https://nvd.nist.gov/vuln/detail/CVE-2020-5902 |
NVD 상세 정보
CVSS v3.1: 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS v2.0: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C설명: In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
CWE: CWE-22 | CWE-22
참조
- http://packetstormsecurity.com/files/158333/BIG-IP-TMUI-Remote-Code-Execution.html [Exploit, Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/158334/BIG-IP-TMUI-Remote-Code-Execution.html [Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/158366/F5-BIG-IP-TMUI-Directory-Traversal-File-Upload-Code-Execution.html [Exploit, Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/158414/Checker-CVE-2020-5902.html [Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/158581/F5-Big-IP-13.1.3-Build-0.0.6-Local-File-Inclusion.html [Exploit, Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/175671/F5-BIG-IP-TMUI-Directory-Traversal-File-Upload-Code-Execution.html [Exploit, Third Party Advisory, VDB Entry]
- https://badpackets.net/over-3000-f5-big-ip-endpoints-vulnerable-to-cve-2020-5902/ [Exploit, Third Party Advisory]
- https://github.com/Critical-Start/Team-Ares/tree/master/CVE-2020-5902 [Broken Link, Exploit, Third Party Advisory]
- https://support.f5.com/csp/article/K52145254 [Vendor Advisory]
- https://swarm.ptsecurity.com/rce-in-f5-big-ip/ [Exploit, Third Party Advisory]
- https://www.criticalstart.com/f5-big-ip-remote-code-execution-exploit/ [Exploit, Third Party Advisory]
- https://www.kb.cert.org/vuls/id/290915 [Third Party Advisory, US Government Resource]
- http://packetstormsecurity.com/files/158333/BIG-IP-TMUI-Remote-Code-Execution.html [Exploit, Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/158334/BIG-IP-TMUI-Remote-Code-Execution.html [Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/158366/F5-BIG-IP-TMUI-Directory-Traversal-File-Upload-Code-Execution.html [Exploit, Third Party Advisory, VDB Entry]
- ... 외 10건
This product uses the NVD API but is not endorsed or certified by the NVD.